Thread: Re: [sqlmap-users] (no subject) (Page 2)
Brought to you by:
inquisb
From: Miroslav S. <mir...@gm...> - 2012-02-14 10:11:31
|
Hi Shadow. This is a pretty old revision (r4009 vs current r4745). Could you please report if this happens on new revision too. Kind regards, Miroslav Stampar On Tue, Feb 14, 2012 at 3:33 AM, Shadow Folder <sha...@gm...>wrote: > [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4009), retry your run > with the latest development version from the Subversion repository. If the > exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the > bug, fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4009) > Python version: 2.6.5 > Operating system: posix > Command line: sqlmap.py -u > ************************************************************** --proxy= > http://00000:80 --random-agent -D ********* -T **** -C ************* > --dump --start=1 --stop=20 > Technique: UNION > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "sqlmap.py", line 86, in main > start() > File "/pentest/database/sqlmap/lib/controller/controller.py", line 539, > in start > action() > File "/pentest/database/sqlmap/lib/controller/action.py", line 109, in > action > conf.dbmsHandler.dumpTable() > File "/pentest/database/sqlmap/plugins/generic/enumeration.py", line > 1551, in dumpTable > entries = inject.getValue(query, blind=False, dump=True) > File "/pentest/database/sqlmap/lib/request/inject.py", line 434, in > getValue > value = __goInband(query, expected, sort, resumeValue, unpack, dump) > File "/pentest/database/sqlmap/lib/request/inject.py", line 386, in > __goInband > output = unionUse(expression, unpack=unpack, dump=dump) > File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line > 332, in unionUse > runThreads(numThreads, unionThread) > File "/pentest/database/sqlmap/lib/core/threads.py", line 62, in > runThreads > threadFunction() > File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line > 302, in unionThread > output = __oneShotUnionUse(limitedExpr, unpack) > File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line > 79, in __oneShotUnionUse > extractRegexResult(check, removeReflectiveValues(page, payload), > re.DOTALL | re.IGNORECASE), \ > File "/pentest/database/sqlmap/lib/core/common.py", line 2514, in > removeReflectiveValues > if regex.split(REFLECTED_NON_ALPHA_NUM_REGEX)[0].lower() in > content.lower(): # fast optimization check > UnicodeDecodeError: 'ascii' codec can't decode byte 0x96 in position 90: > ordinal not in range(128) > > [*] shutting down at: 04:32:26 > > > > ------------------------------------------------------------------------------ > Keep Your Developer Skills Current with LearnDevNow! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-d2d > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: 叶晓勇 <gr...@gm...> - 2012-02-18 14:44:07
|
Hi I got the "unable to find results for your Google dork expression" problem in sqlmap/1.0-dev (r4766) ,can anybody help? regards! |
From: Miroslav S. <mir...@gm...> - 2012-02-20 09:47:35
|
Hi. Find it fixed with the latest r4767. Kind regards, Miroslav Stampar On Sat, Feb 18, 2012 at 3:44 PM, 叶晓勇 <gr...@gm...> wrote: > Hi > > I got the "unable to find results for your Google dork expression" problem > in sqlmap/1.0-dev (r4766) ,can anybody help? > > regards! > > > ------------------------------------------------------------------------------ > Virtualization & Cloud Management Using Capacity Planning > Cloud computing makes use of virtualization - but cloud computing > also focuses on allowing computing to be delivered as a service. > http://www.accelacomm.com/jaw/sfnl/114/51521223/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Shadow F. <sha...@gm...> - 2012-04-03 15:44:51
|
sqlmap version: 1.0-dev (r4930) Python version: 2.6.5 Operating system: posix Command line: sqlmap.py -u ******************************************************** --tor --dbms=mysql --file-write=shell.php --file-dest=/srv/www/htdocs/shell.php --level 3 --risk 2 Technique: ERROR Back-end DBMS: MySQL (fingerprinted) Traceback (most recent call last): File "/pentest/database/sqlmap/_sqlmap.py", line 82, in main start() File "/pentest/database/sqlmap/lib/controller/controller.py", line 573, in start action() File "/pentest/database/sqlmap/lib/controller/action.py", line 132, in action conf.dbmsHandler.writeFile(conf.wFile, conf.dFile, conf.wFileType) File "/pentest/database/sqlmap/plugins/generic/filesystem.py", line 326, in writeFile self.unionWriteFile(wFile, dFile, fileType, confirm) File "/pentest/database/sqlmap/plugins/dbms/mysql/filesystem.py", line 98, in unionWriteFile self.askCheckWrittenFile(wFile, dFile, fileType) File "/pentest/database/sqlmap/plugins/generic/filesystem.py", line 239, in askCheckWrittenFile self.__checkWrittenFile(wFile, dFile, fileType) File "/pentest/database/sqlmap/plugins/generic/filesystem.py", line 115, in __checkWrittenFile if dFileSize and dFileSize.isdigit(): AttributeError: 'list' object has no attribute 'isdigit' [*] shutting down at 09:40:59 |
From: Miroslav S. <mir...@gm...> - 2012-04-04 09:08:12
|
Hi. Thank you and find it fixed with the latest commit (4952). Kind regards, Miroslav Stampar On Tue, Apr 3, 2012 at 5:44 PM, Shadow Folder <sha...@gm...>wrote: > sqlmap version: 1.0-dev (r4930) > Python version: 2.6.5 > Operating system: posix > Command line: sqlmap.py -u > ******************************************************** --tor --dbms=mysql > --file-write=shell.php --file-dest=/srv/www/htdocs/shell.php --level 3 > --risk 2 > Technique: ERROR > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "/pentest/database/sqlmap/_sqlmap.py", line 82, in main > start() > File "/pentest/database/sqlmap/lib/controller/controller.py", line 573, > in start > action() > File "/pentest/database/sqlmap/lib/controller/action.py", line 132, in > action > conf.dbmsHandler.writeFile(conf.wFile, conf.dFile, conf.wFileType) > File "/pentest/database/sqlmap/plugins/generic/filesystem.py", line 326, > in writeFile > self.unionWriteFile(wFile, dFile, fileType, confirm) > File "/pentest/database/sqlmap/plugins/dbms/mysql/filesystem.py", line > 98, in unionWriteFile > self.askCheckWrittenFile(wFile, dFile, fileType) > File "/pentest/database/sqlmap/plugins/generic/filesystem.py", line 239, > in askCheckWrittenFile > self.__checkWrittenFile(wFile, dFile, fileType) > File "/pentest/database/sqlmap/plugins/generic/filesystem.py", line 115, > in __checkWrittenFile > if dFileSize and dFileSize.isdigit(): > AttributeError: 'list' object has no attribute 'isdigit' > > [*] shutting down at 09:40:59 > > > > ------------------------------------------------------------------------------ > Better than sec? Nothing is better than sec when it comes to > monitoring Big Data applications. Try Boundary one-second > resolution app monitoring today. Free. > http://p.sf.net/sfu/Boundary-dev2dev > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Shadow F. <sha...@gm...> - 2012-06-16 08:57:51
|
[01:03:40] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r5127), retry your run with the latest development version from the Subversion repository. If the exception persists, please send by e-mail to sql...@li... the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev (r5127) Python version: 2.6.5 Operating system: posix Command line: ./sqlmap.py -u ****************************************************************************************************************************************************** --tor --random-agent -p hLids --technique=U -v 3 --current-user Technique: UNION Back-end DBMS: MySQL (fingerprinted) Traceback (most recent call last): File "/pentest/database/sqlmap/_sqlmap.py", line 81, in main start() File "/pentest/database/sqlmap/lib/controller/controller.py", line 573, in start action() File "/pentest/database/sqlmap/lib/controller/action.py", line 64, in action conf.dumper.currentUser(conf.dbmsHandler.getCurrentUser()) File "/pentest/database/sqlmap/plugins/generic/enumeration.py", line 138, in getCurrentUser kb.data.currentUser = unArrayizeValue(inject.getValue(query)) File "/pentest/database/sqlmap/lib/request/inject.py", line 418, in getValue value = __goInband(query, expected, unpack, dump) File "/pentest/database/sqlmap/lib/request/inject.py", line 365, in __goInband output = unionUse(expression, unpack=unpack, dump=dump) File "/pentest/database/sqlmap/lib/techniques/union/use.py", line 343, in unionUse value = __oneShotUnionUse(expression, unpack) File "/pentest/database/sqlmap/lib/techniques/union/use.py", line 69, in __oneShotUnionUse kb.unionDuplicates = vector[7] IndexError: tuple index out of range |
From: Miroslav S. <mir...@gm...> - 2012-06-25 15:47:02
|
Hi Shadow. Sorry for late reply. I believe that we've fixed this one couple of days ago. Kind regards, Miroslav Stampar On Sat, Jun 16, 2012 at 10:57 AM, Shadow Folder <sha...@gm...>wrote: > [01:03:40] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r5127), retry > your run with the latest development version from the Subversion > repository. If the exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the > bug, fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r5127) > Python version: 2.6.5 > Operating system: posix > Command line: ./sqlmap.py -u > ****************************************************************************************************************************************************** > --tor --random-agent -p hLids --technique=U -v 3 --current-user > Technique: UNION > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "/pentest/database/sqlmap/_sqlmap.py", line 81, in main > start() > File "/pentest/database/sqlmap/lib/controller/controller.py", line 573, > in start > action() > File "/pentest/database/sqlmap/lib/controller/action.py", line 64, in > action > conf.dumper.currentUser(conf.dbmsHandler.getCurrentUser()) > File "/pentest/database/sqlmap/plugins/generic/enumeration.py", line > 138, in getCurrentUser > kb.data.currentUser = unArrayizeValue(inject.getValue(query)) > File "/pentest/database/sqlmap/lib/request/inject.py", line 418, in > getValue > value = __goInband(query, expected, unpack, dump) > File "/pentest/database/sqlmap/lib/request/inject.py", line 365, in > __goInband > output = unionUse(expression, unpack=unpack, dump=dump) > File "/pentest/database/sqlmap/lib/techniques/union/use.py", line 343, > in unionUse > value = __oneShotUnionUse(expression, unpack) > File "/pentest/database/sqlmap/lib/techniques/union/use.py", line 69, in > __oneShotUnionUse > kb.unionDuplicates = vector[7] > IndexError: tuple index out of range > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Marco M. <mm...@gm...> - 2012-07-03 20:35:05
|
Hello sqlMap I thought of an improvement, because when you retrieve the databases (or tables or columns) does not enumerate the number of the item? ====================================== current sqlMap ====================================== [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server web server operating system: Windows 2003 web application technology: ASP.NET, Microsoft IIS 6.0, ASP back-end DBMS: Microsoft SQL Server 2005 [22:15:39] [INFO] fetching columns for table 'myTable' in database 'mystore' [22:15:49] [WARNING] reflective value(s) found and filtering out [22:15:49] [INFO] the SQL query used returns 253 entries [22:16:00] [INFO] retrieved: citta [22:16:07] [INFO] retrieved: varchar [22:16:13] [INFO] retrieved: cognome [22:16:22] [INFO] retrieved: nvarchar .... ====================================== my idea (modify in green) ====================================== [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server web server operating system: Windows 2003 web application technology: ASP.NET, Microsoft IIS 6.0, ASP back-end DBMS: Microsoft SQL Server 2005 [22:15:39] [INFO] fetching columns for table 'myTable' in database 'mystore' [22:15:49] [WARNING] reflective value(s) found and filtering out [22:15:49] [INFO] the SQL query used returns 253 entries [22:16:00] [INFO] retrieved #1: citta [22:16:07] [INFO] retrieved #2: varchar [22:16:13] [INFO] retrieved #3: cognome [22:16:22] [INFO] retrieved #4: nvarchar .... lot a kiss |
From: Iago S. <146...@gm...> - 2012-07-04 15:18:33
|
If you know python you can modify and submit to github, then the developers will analize. On Tue, Jul 3, 2012 at 5:35 PM, Marco Mirandola <mm...@gm...> wrote: > Hello sqlMap I thought of an improvement, because when you retrieve the > databases (or tables or columns) does not enumerate the number of the item? > > ====================================== > current sqlMap > ====================================== > > [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server > web server operating system: Windows 2003 > web application technology: ASP.NET, Microsoft IIS 6.0, ASP > back-end DBMS: Microsoft SQL Server 2005 > [22:15:39] [INFO] fetching columns for table 'myTable' in database > 'mystore' > [22:15:49] [WARNING] reflective value(s) found and filtering out > [22:15:49] [INFO] the SQL query used returns 253 entries > [22:16:00] [INFO] retrieved: citta > [22:16:07] [INFO] retrieved: varchar > [22:16:13] [INFO] retrieved: cognome > [22:16:22] [INFO] retrieved: nvarchar > .... > > > ====================================== > my idea (modify in green) > ====================================== > > [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server > web server operating system: Windows 2003 > web application technology: ASP.NET, Microsoft IIS 6.0, ASP > back-end DBMS: Microsoft SQL Server 2005 > [22:15:39] [INFO] fetching columns for table 'myTable' in database > 'mystore' > [22:15:49] [WARNING] reflective value(s) found and filtering out > [22:15:49] [INFO] the SQL query used returns 253 entries > [22:16:00] [INFO] retrieved #1: citta > [22:16:07] [INFO] retrieved #2: varchar > [22:16:13] [INFO] retrieved #3: cognome > [22:16:22] [INFO] retrieved #4: nvarchar > .... > > lot a kiss > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Regards, Iago Sousa Webdesigner at Radar Topografia Programmer and Security Researcher |
From: Miroslav S. <mir...@gm...> - 2012-07-05 08:25:24
|
Hi Marco. We'll consider this one and maybe put it back on (we had it long time before). Kind regards, Miroslav Stampar On Tue, Jul 3, 2012 at 10:35 PM, Marco Mirandola <mm...@gm...> wrote: > Hello sqlMap I thought of an improvement, because when you retrieve the > databases (or tables or columns) does not enumerate the number of the item? > > ====================================== > current sqlMap > ====================================== > > [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server > web server operating system: Windows 2003 > web application technology: ASP.NET, Microsoft IIS 6.0, ASP > back-end DBMS: Microsoft SQL Server 2005 > [22:15:39] [INFO] fetching columns for table 'myTable' in database > 'mystore' > [22:15:49] [WARNING] reflective value(s) found and filtering out > [22:15:49] [INFO] the SQL query used returns 253 entries > [22:16:00] [INFO] retrieved: citta > [22:16:07] [INFO] retrieved: varchar > [22:16:13] [INFO] retrieved: cognome > [22:16:22] [INFO] retrieved: nvarchar > .... > > > ====================================== > my idea (modify in green) > ====================================== > > [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server > web server operating system: Windows 2003 > web application technology: ASP.NET, Microsoft IIS 6.0, ASP > back-end DBMS: Microsoft SQL Server 2005 > [22:15:39] [INFO] fetching columns for table 'myTable' in database > 'mystore' > [22:15:49] [WARNING] reflective value(s) found and filtering out > [22:15:49] [INFO] the SQL query used returns 253 entries > [22:16:00] [INFO] retrieved #1: citta > [22:16:07] [INFO] retrieved #2: varchar > [22:16:13] [INFO] retrieved #3: cognome > [22:16:22] [INFO] retrieved #4: nvarchar > .... > > lot a kiss > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-07-07 09:48:13
|
https://github.com/sqlmapproject/sqlmap/issues/71 Kind regards, Miroslav Stampar On Thu, Jul 5, 2012 at 10:25 AM, Miroslav Stampar < mir...@gm...> wrote: > Hi Marco. > > We'll consider this one and maybe put it back on (we had it long time > before). > > Kind regards, > Miroslav Stampar > > On Tue, Jul 3, 2012 at 10:35 PM, Marco Mirandola <mm...@gm...>wrote: > >> Hello sqlMap I thought of an improvement, because when you retrieve the >> databases (or tables or columns) does not enumerate the number of the item? >> >> ====================================== >> current sqlMap >> ====================================== >> >> [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server >> web server operating system: Windows 2003 >> web application technology: ASP.NET, Microsoft IIS 6.0, ASP >> back-end DBMS: Microsoft SQL Server 2005 >> [22:15:39] [INFO] fetching columns for table 'myTable' in database >> 'mystore' >> [22:15:49] [WARNING] reflective value(s) found and filtering out >> [22:15:49] [INFO] the SQL query used returns 253 entries >> [22:16:00] [INFO] retrieved: citta >> [22:16:07] [INFO] retrieved: varchar >> [22:16:13] [INFO] retrieved: cognome >> [22:16:22] [INFO] retrieved: nvarchar >> .... >> >> >> ====================================== >> my idea (modify in green) >> ====================================== >> >> [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server >> web server operating system: Windows 2003 >> web application technology: ASP.NET, Microsoft IIS 6.0, ASP >> back-end DBMS: Microsoft SQL Server 2005 >> [22:15:39] [INFO] fetching columns for table 'myTable' in database >> 'mystore' >> [22:15:49] [WARNING] reflective value(s) found and filtering out >> [22:15:49] [INFO] the SQL query used returns 253 entries >> [22:16:00] [INFO] retrieved #1: citta >> [22:16:07] [INFO] retrieved #2: varchar >> [22:16:13] [INFO] retrieved #3: cognome >> [22:16:22] [INFO] retrieved #4: nvarchar >> .... >> >> lot a kiss >> >> >> ------------------------------------------------------------------------------ >> Live Security Virtual Conference >> Exclusive live event will cover all the ways today's security and >> threat landscape has changed and how IT managers can respond. Discussions >> will include endpoint security, mobile security and the latest in malware >> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> >> > > > -- > Miroslav Stampar > http://about.me/stamparm > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-07-07 22:19:10
|
Hi Marco. There are some issues around this feature request briefly described here: https://github.com/sqlmapproject/sqlmap/issues/71#issuecomment-6827035 Kind regards, Miroslav Stampar On Thu, Jul 5, 2012 at 10:25 AM, Miroslav Stampar < mir...@gm...> wrote: > Hi Marco. > > We'll consider this one and maybe put it back on (we had it long time > before). > > Kind regards, > Miroslav Stampar > > On Tue, Jul 3, 2012 at 10:35 PM, Marco Mirandola <mm...@gm...>wrote: > >> Hello sqlMap I thought of an improvement, because when you retrieve the >> databases (or tables or columns) does not enumerate the number of the item? >> >> ====================================== >> current sqlMap >> ====================================== >> >> [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server >> web server operating system: Windows 2003 >> web application technology: ASP.NET, Microsoft IIS 6.0, ASP >> back-end DBMS: Microsoft SQL Server 2005 >> [22:15:39] [INFO] fetching columns for table 'myTable' in database >> 'mystore' >> [22:15:49] [WARNING] reflective value(s) found and filtering out >> [22:15:49] [INFO] the SQL query used returns 253 entries >> [22:16:00] [INFO] retrieved: citta >> [22:16:07] [INFO] retrieved: varchar >> [22:16:13] [INFO] retrieved: cognome >> [22:16:22] [INFO] retrieved: nvarchar >> .... >> >> >> ====================================== >> my idea (modify in green) >> ====================================== >> >> [22:15:39] [INFO] the back-end DBMS is Microsoft SQL Server >> web server operating system: Windows 2003 >> web application technology: ASP.NET, Microsoft IIS 6.0, ASP >> back-end DBMS: Microsoft SQL Server 2005 >> [22:15:39] [INFO] fetching columns for table 'myTable' in database >> 'mystore' >> [22:15:49] [WARNING] reflective value(s) found and filtering out >> [22:15:49] [INFO] the SQL query used returns 253 entries >> [22:16:00] [INFO] retrieved #1: citta >> [22:16:07] [INFO] retrieved #2: varchar >> [22:16:13] [INFO] retrieved #3: cognome >> [22:16:22] [INFO] retrieved #4: nvarchar >> .... >> >> lot a kiss >> >> >> ------------------------------------------------------------------------------ >> Live Security Virtual Conference >> Exclusive live event will cover all the ways today's security and >> threat landscape has changed and how IT managers can respond. Discussions >> will include endpoint security, mobile security and the latest in malware >> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> >> > > > -- > Miroslav Stampar > http://about.me/stamparm > -- Miroslav Stampar http://about.me/stamparm |
From: manupriya h. <man...@gm...> - 2012-11-09 13:52:06
|
hey m new to dis field,but have an urgency touse and understand this tool so plz guide me from the start,i dnt even 9 hw to install it i didnt get the exe file for it plz guide me |
From: Bernardo D. A. G. <ber...@gm...> - 2012-11-09 13:54:17
|
yo broder, sup? this field not 4 all, g0 play with wii witch yo understand bettar plz On 9 November 2012 13:52, manupriya hasija <man...@gm...> wrote: > hey > m new to dis field,but have an urgency touse and understand this tool > so plz guide me from the start,i dnt even 9 hw to install it > i didnt get the exe file for it > plz guide me > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_d2d_nov > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) |
From: Stan S. <sep...@gm...> - 2013-01-16 10:56:38
|
Having the same problem as described here with the currnt version of SQLMap. http://www.question-defense.com/2011/10/03/sqlmap-wont-enumerate-databases Any suggestions? |
From: Miroslav S. <mir...@gm...> - 2013-01-16 12:06:57
|
Hi. Which version do you use? Technique? Maybe you could send a traffic file for that run (-t traffic.txt --fresh-queries). Bye Dana 16.1.2013. 11:57 "Stan Smith" <sep...@gm...> je napisao/la: > Having the same problem as described here with the currnt version of > SQLMap. > > http://www.question-defense.com/2011/10/03/sqlmap-wont-enumerate-databases > > Any suggestions? > > > ------------------------------------------------------------------------------ > Master Java SE, Java EE, Eclipse, Spring, Hibernate, JavaScript, jQuery > and much more. Keep your Java skills current with LearnJavaNow - > 200+ hours of step-by-step video tutorials by Java experts. > SALE $49.99 this month only -- learn more at: > http://p.sf.net/sfu/learnmore_122612 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > |
From: Stan S. <sep...@gm...> - 2013-01-16 13:23:47
|
I can not seem to make it create the traffic file. :( But I am using the version which was in the .zip file that I had downloaded here today. 16/1/2013 https://github.com/sqlmapproject/sqlmap/zipball/master sqlmapproject-sqlmap-3464a70 I know that this is very little information to go on. Please advise me on how to provide you with more information. |
From: Miroslav S. <mir...@gm...> - 2013-01-16 13:29:34
|
Hi. Well, you just append --fresh-queries -t traffic.txt to your normal sqlmap run (e.g. python sqlmap.py -u "www.target.com/vuln.php?id=1" .... -t traffic.txt --fresh-queries I am interested in resulting "traffic.txt" file inside running directory. Kind regards, Miroslav Stampar On Wed, Jan 16, 2013 at 2:23 PM, Stan Smith <sep...@gm...> wrote: > I can not seem to make it create the traffic file. :( > > But I am using the version which was in the .zip file that I had downloaded here today. 16/1/2013 > > https://github.com/sqlmapproject/sqlmap/zipball/master > > sqlmapproject-sqlmap-3464a70 > > I know that this is very little information to go on. Please advise me on how to provide you with more information. > > > > ------------------------------------------------------------------------------ > Master Java SE, Java EE, Eclipse, Spring, Hibernate, JavaScript, jQuery > and much more. Keep your Java skills current with LearnJavaNow - > 200+ hours of step-by-step video tutorials by Java experts. > SALE $49.99 this month only -- learn more at: > http://p.sf.net/sfu/learnmore_122612 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Stan S. <sep...@gm...> - 2013-01-16 13:48:25
|
I tried the traffic switch but there is no file created in rhe traffic folder. Honoured 2 be speaking to you by the way. :) |
From: Miroslav S. <mir...@gm...> - 2013-01-16 13:59:25
|
Hi. Traffic file should be inside the folder where you run sqlmap.py. So, if you are running sqlmap.py from folder ABC, then traffic.txt should be located in that same directory. E.g.: C:\sqlmap> python sqlmap.py -u "..." ... -t traffic.txt .... C:\sqlmap>dir *.txt traffic.txt Kind regards, Miroslav Stampar On Wed, Jan 16, 2013 at 2:48 PM, Stan Smith <sep...@gm...> wrote: > I tried the traffic switch but there is no file created in rhe traffic > folder. Honoured 2 be speaking to you by the way. :) > > > ------------------------------------------------------------------------------ > Master Java SE, Java EE, Eclipse, Spring, Hibernate, JavaScript, jQuery > and much more. Keep your Java skills current with LearnJavaNow - > 200+ hours of step-by-step video tutorials by Java experts. > SALE $49.99 this month only -- learn more at: > http://p.sf.net/sfu/learnmore_122612 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Stan S. <sep...@gm...> - 2013-01-16 15:01:21
|
I can not make it do it. I'm sure it's something that I'm doing as obviously it should work but I can not get it to output a text file :( I |
From: mastermind <cyb...@ma...> - 2013-12-01 08:14:23
|
[15:10:45] [CRITICAL] unhandled exception in sqlmap/1.0-dev, retry your run with the latest developm ent version from the GitHub repository. If the exception persists, please send by e-mail to 'sqlmap- us...@li...' or open a new issue at 'https://github.com/sqlmapproject/sqlmap/issues/ new' with the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev Python version: 2.7.5 Operating system: nt Command line: C:\Users\Mastermind\Desktop\Hack\SQLmap\sqlmap.py -g ****************** --random-agent -o --keep-alive --threads=10 --batch --is-dba --dbs --beep --page-rank --smart Technique: None Back-end DBMS: None (identified) Traceback (most recent call last): File "C:\Users\Mastermind\Desktop\Hack\SQLmap\sqlmap.py", line 95, in main start() File "C:\Users\Mastermind\Desktop\Hack\SQLmap\lib\controller\controller.py", line 363, in start if not checkConnection(suppressOutput=conf.forms) or not checkString() or not checkRegexp(): File "C:\Users\Mastermind\Desktop\Hack\SQLmap\lib\controller\checks.py", line 1207, in checkConnec tion page, _ = Request.queryPage(content=True, noteResponseTime=False) File "C:\Users\Mastermind\Desktop\Hack\SQLmap\lib\request\connect.py", line 880, in queryPage page, headers, code = Connect.getPage(url=uri, get=get, post=post, cookie=cookie, ua=ua, referer =referer, host=host, silent=silent, method=method, auxHeaders=auxHeaders, response=response, raise40 4=raise404, ignoreTimeout=timeBasedCompare) File "C:\Users\Mastermind\Desktop\Hack\SQLmap\lib\request\connect.py", line 383, in getPage conn = urllib2.urlopen(req) File "C:\Python27\lib\urllib2.py", line 127, in urlopen return _opener.open(url, data, timeout) File "C:\Python27\lib\urllib2.py", line 404, in open response = self._open(req, data) File "C:\Python27\lib\urllib2.py", line 422, in _open '_open', req) File "C:\Python27\lib\urllib2.py", line 382, in _call_chain result = func(*args) File "C:\Users\Mastermind\Desktop\Hack\SQLmap\thirdparty\keepalive\keepalive.py", line 210, in htt p_open return self.do_open(HTTPConnection, req) File "C:\Users\Mastermind\Desktop\Hack\SQLmap\thirdparty\keepalive\keepalive.py", line 207, in do_ open return self.parent.error('http', req, r, r.status, r.reason, r.msg) File "C:\Python27\lib\urllib2.py", line 442, in error result = self._call_chain(*args) File "C:\Python27\lib\urllib2.py", line 382, in _call_chain result = func(*args) File "C:\Users\Mastermind\Desktop\Hack\SQLmap\lib\request\redirecthandler.py", line 92, in http_er ror_302 redirectMsg += "[#%d] (%d %s):\n" % (threadData.lastRequestUID, code, getUnicode(msg)) File "C:\Users\Mastermind\Desktop\Hack\SQLmap\lib\core\common.py", line 1962, in getUnicode return unicode(value) # encoding ignored for non-basestring instances UnicodeDecodeError: 'ascii' codec can't decode byte 0xcd in position 14: ordinal not in range(128) |
From: mastermind <cyb...@ma...> - 2013-12-02 02:27:19
|
C:\Python27\lib\urllib.py:1282: UnicodeWarning: Unicode equal comparison failed to convert both argu ments to Unicode - interpreting them as being unequal return ''.join(map(quoter, s)) [09:25:32] [CRITICAL] unhandled exception in sqlmap/1.0-dev, retry your run with the latest developm ent version from the GitHub repository. If the exception persists, please send by e-mail to 'sqlmap- us...@li...' or open a new issue at 'https://github.com/sqlmapproject/sqlmap/issues/ new' with the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev Python version: 2.7.5 Operating system: nt Command line: C:\Users\Mastermind\Desktop\Hack\SQLmap\sqlmap.py -g ************************** --rand om-agent --threads=10 --batch --is-dba --dbs --beep --page-rank --smart Technique: None Back-end DBMS: None (identified) Traceback (most recent call last): File "C:\Users\Mastermind\Desktop\Hack\SQLmap\sqlmap.py", line 95, in main start() File "C:\Users\Mastermind\Desktop\Hack\SQLmap\lib\controller\controller.py", line 309, in start message = "URL %d:\n%s %s%s" % (hostCount, conf.method or HTTPMETHOD.GET, targetUrl, " (PageRank : %s)" % get_pagerank(targetUrl) if conf.googleDork and conf.pageRank else "") File "C:\Users\Mastermind\Desktop\Hack\SQLmap\thirdparty\pagerank\pagerank.py", line 18, in get_pa gerank _ = 'http://toolbarqueries.google.com/tbr?client=navclient-auto&features=Rank&ch=%s&q=info:%s' % (check_hash(hash_url(url)), urllib.quote(url)) File "C:\Python27\lib\urllib.py", line 1282, in quote return ''.join(map(quoter, s)) KeyError: u'\xd4' |
From: Manuel Z. <man...@gm...> - 2014-03-07 07:28:10
|
<?xml version="1.0"?> <!DOCTYPE items [ <!ELEMENT items (item*)> <!ATTLIST items burpVersion CDATA ""> <!ATTLIST items exportTime CDATA ""> <!ELEMENT item (time, url, host, port, protocol, method, path, extension, request, status, responselength, mimetype, response, comment)> <!ELEMENT time (#PCDATA)> <!ELEMENT url (#PCDATA)> <!ELEMENT host (#PCDATA)> <!ATTLIST host ip CDATA ""> <!ELEMENT port (#PCDATA)> <!ELEMENT protocol (#PCDATA)> <!ELEMENT method (#PCDATA)> <!ELEMENT path (#PCDATA)> <!ELEMENT extension (#PCDATA)> <!ELEMENT request (#PCDATA)> <!ATTLIST request base64 (true|false) "false"> <!ELEMENT status (#PCDATA)> <!ELEMENT responselength (#PCDATA)> <!ELEMENT mimetype (#PCDATA)> <!ELEMENT response (#PCDATA)> <!ATTLIST response base64 (true|false) "false"> <!ELEMENT comment (#PCDATA)> ]> <items burpVersion="1.5" exportTime="Fri Mar 07 07:45:18 CET 2014"> <item> <time>Fri Mar 07 07:34:26 CET 2014</time> <url><![CDATA[http://localhost/WebGoat/attack?Screen=6&menu=1100]]></url> <host ip="127.0.0.1">localhost</host> <port>80</port> <protocol>http</protocol> <method>POST</method> <path><![CDATA[/WebGoat/attack?Screen=6&menu=1100]]></path> <extension>null</extension> <request base64="true"><![CDATA[UE9TVCAvV2ViR29hdC9hdHRhY2s/U2NyZWVuPTYmbWVudT0xMTAwIEhUVFAvMS4xDQpIb3N0OiBsb2NhbGhvc3QNClVzZXItQWdlbnQ6IE1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMTsgV09XNjQ7IHJ2OjI3LjApIEdlY2tvLzIwMTAwMTAxIEZpcmVmb3gvMjcuMA0KQWNjZXB0OiB0ZXh0L2h0bWwsYXBwbGljYXRpb24veGh0bWwreG1sLGFwcGxpY2F0aW9uL3htbDtxPTAuOSwqLyo7cT0wLjgNCkFjY2VwdC1MYW5ndWFnZTogZGUtZGUsZGU7cT0wLjgsZW4tdXM7cT0wLjUsZW47cT0wLjMNCkFjY2VwdC1FbmNvZGluZzogZ3ppcCwgZGVmbGF0ZQ0KUmVmZXJlcjogaHR0cDovL2xvY2FsaG9zdC9XZWJHb2F0L2F0dGFjaw0KQ29va2llOiBKU0VTU0lPTklEPTE0MTI3MjUxNDIzNDE2MkIwODJGMzU0OERDQ0Y2MEM4DQpBdXRob3JpemF0aW9uOiBCYXNpYyBaM1ZsYzNRNlozVmxjM1E9DQpDb25uZWN0aW9uOiBrZWVwLWFsaXZlDQpDb250ZW50LVR5cGU6IGFwcGxpY2F0aW9uL3gtd3d3LWZvcm0tdXJsZW5jb2RlZA0KQ29udGVudC1MZW5ndGg6IDI2DQoNCnVzZXJpZD1qc21pdGgmU1VCTUlUPUdvJTIx]]></request> <status>200</status> <responselength>30452</responselength> <mimetype>HTML</mimetype> <response base64="true"><![CDATA[]]></response> <comment></comment> </item> </items> |
From: Miroslav S. <mir...@gm...> - 2014-03-07 14:59:02
|
Hi. Thank you for your report. Find it fixed with the latest commit. Kind regards, Miroslav Stampar On Fri, Mar 7, 2014 at 8:28 AM, Manuel Zwettler <man...@gm...>wrote: > Hi, > > I got an error running sqlmap on WebGoat vulnerable web application with > the following data. Please find the file containing the used request > attached to the mail. > > sqlmap version: 1.0-dev > Python version: 2.7.6 > Operating system: nt > Command line: > C:\Users\Administrator\Downloads\sqlmapproject-sqlmap-0.9-3446-g490d512\sqlmapproject-sqlmap-490d512\sqlmap.py > -v 3 -r request_burp.txt --auth-type Basic --auth-cred *********** > --fingerprint --os-cmd calc.exe --file-read c:\mytest.txt --tables salaries > Technique: BOOLEAN > Back-end DBMS: HSQLDB (fingerprinted) > Traceback (most recent call last): > File > "C:\Users\Administrator\Downloads\sqlmapproject-sqlmap-0.9-3446-g490d512\sqlmapproject-sqlmap-490d512\sqlmap.py", > line 95, in main > start() > File > "C:\Users\Administrator\Downloads\sqlmapproject-sqlmap-0.9-3446-g490d512\sqlmapproject-sqlmap-490d512\lib\controller\controller.py", > line 583, in start > action() > File > "C:\Users\Administrator\Downloads\sqlmapproject-sqlmap-0.9-3446-g490d512\sqlmapproject-sqlmap-490d512\lib\controller\action.py", > line 109, in action > conf.dumper.dbTables(conf.dbmsHandler.getTables()) > File > "C:\Users\Administrator\Downloads\sqlmapproject-sqlmap-0.9-3446-g490d512\sqlmapproject-sqlmap-490d512\plugins\generic\databases.py", > line 335, in getTabl > es > query = rootQuery.blind.query % (unsafeSQLIdentificatorNaming(db), > index) > TypeError: %d format: a number is required, not unicode > > Thanks for taking a look at it in advance! > I'd appreciate hearing more about the progress concerning this problem > > Kind regards, > Manuel Zwettler > > > ------------------------------------------------------------------------------ > Subversion Kills Productivity. Get off Subversion & Make the Move to > Perforce. > With Perforce, you get hassle-free workflows. Merge that actually works. > Faster operations. Version large binaries. Built-in WAN optimization and > the > freedom to use Git, Perforce or both. Make the move to Perforce. > > http://pubads.g.doubleclick.net/gampad/clk?id=122218951&iu=/4140/ostg.clktrk > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |